CVE-2021-31808Integer Overflow or Wraparound in Squid

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 43.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 27
Latest updateMay 24

Description

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDsquid-cache/squid5.05.0.6+1
Debiansquid/squid< 4.13-10+3

Also affects: Debian Linux 10.0, 9.0, Fedora 33, 34

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hx5h-cw5j-ghcr: An issue was discovered in Squid before 42022-05-24
CVEList
CVE-2021-31808: An issue was discovered in Squid before 42021-05-27
OSV
CVE-2021-31808: An issue was discovered in Squid before 42021-05-27

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2021-06-03
Red Hat
squid: integer overflow in HTTP Range header2021-05-10
Debian
CVE-2021-31808: squid - An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an inp...2021
CVE-2021-31808 — Integer Overflow or Wraparound | cvebase